[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 25 20:59:43 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
cb8c765c by Salvatore Bonaccorso at 2026-09-25T21:59:26+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -47,69 +47,69 @@ CVE-2026-97764 (django-allauth before 65.19.4 does not have the expected limits
 	NOTE: Fixed by: https://codeberg.org/allauth/django-allauth/commit/4379e7931fe7572aacc4f3b4b5f2298d5f3ecc96 (65.19.4)
 	NOTE: Fixed by: https://codeberg.org/allauth/django-allauth/commit/4e252aa2be7cef5d72d78049d6fb07cb27a89c83 (65.19.4)
 CVE-2026-97737 (In Wakapi before 2.17.6, the user caching service allows a lookup to b ...)
-	TODO: check
+	NOT-FOR-US: Wakapi
 CVE-2026-97736 (tinyauth before 5.1.3 allows rule bypass by appending an allowed route ...)
-	TODO: check
+	NOT-FOR-US: Tinyauth
 CVE-2026-97735 (ITFlow before 26.08 allows SVG attachments in the ticket email parser  ...)
-	TODO: check
+	NOT-FOR-US: ITFlow
 CVE-2026-97732 (IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that au ...)
-	TODO: check
+	NOT-FOR-US: IRONMACE Ironshield
 CVE-2026-97731 (MinIO through 7aac2a2 does not verify that every x-amz-* header presen ...)
 	TODO: check
 CVE-2026-97730 (In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Lo ...)
-	TODO: check
+	NOT-FOR-US: Netgate pfSense Plus
 CVE-2026-97724 (A prototype pollution vulnerability in Software Mansion React Native W ...)
-	TODO: check
+	NOT-FOR-US: Software Mansion React Native Worklets
 CVE-2026-97723 (madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (X ...)
-	TODO: check
+	NOT-FOR-US: madpsy ka9q_ubersdr
 CVE-2026-97721 (A weakness has been identified in Sanluan PublicCMS up to 6.202506.e.  ...)
-	TODO: check
+	NOT-FOR-US: Sanluan PublicCMS
 CVE-2026-97650 (A vulnerability has been found in ningzichun student-management-system ...)
-	TODO: check
+	NOT-FOR-US: ningzichun student-management-system
 CVE-2026-97649 (A flaw has been found in ningzichun student-management-system up to 98 ...)
-	TODO: check
+	NOT-FOR-US: ningzichun student-management-system
 CVE-2026-97648 (A vulnerability was detected in ningzichun student-management-system u ...)
-	TODO: check
+	NOT-FOR-US: ningzichun student-management-system
 CVE-2026-97647 (A security vulnerability has been detected in ningzichun student-manag ...)
-	TODO: check
+	NOT-FOR-US: ningzichun student-management-system
 CVE-2026-97646 (A weakness has been identified in ningzichun student-management-system ...)
-	TODO: check
+	NOT-FOR-US: ningzichun student-management-system
 CVE-2026-97636 (Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend ...)
-	TODO: check
+	NOT-FOR-US: Apache Airflow HashiCorp provider
 CVE-2026-97622
 	REJECTED
 CVE-2026-97469 (PostgreSQL Anonymizer contains a vulnerability that allows unprivilege ...)
-	TODO: check
+	NOT-FOR-US: PostgreSQL Anonymizer
 CVE-2026-97387
 	REJECTED
 CVE-2026-97368 (A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. ...)
-	TODO: check
+	NOT-FOR-US: chillzhuang SpringBlade
 CVE-2026-97366 (A security flaw has been discovered in jhen0409 react-native-debugger  ...)
-	TODO: check
+	NOT-FOR-US: jhen0409 react-native-debugger
 CVE-2026-97365 (A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2. Impa ...)
-	TODO: check
+	NOT-FOR-US: chonkie-inc littrs
 CVE-2026-97326 (A weakness has been identified in songxinjianqwe Chat up to ac63d25297 ...)
-	TODO: check
+	NOT-FOR-US: songxinjianqwe Chat
 CVE-2026-97325 (A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue- ...)
-	TODO: check
+	NOT-FOR-US: YunaiV/zhijiantianya ruoyi-vue-pro
 CVE-2026-97324 (A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro u ...)
-	TODO: check
+	NOT-FOR-US: YunaiV/zhijiantianya ruoyi-vue-pro
 CVE-2026-97228 (Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a Grap ...)
-	TODO: check
+	NOT-FOR-US: Rapid7 Bulk Export MCP
 CVE-2026-97222 (A heap use-after-free flaw was found in Gnumeric. When a user opens a  ...)
 	TODO: check
 CVE-2026-97064 (X-SpringBoot through 6.0 ships with a hardcoded static master login ve ...)
-	TODO: check
+	NOT-FOR-US: X-SpringBoot
 CVE-2026-97063 (X-SpringBoot through 6.0 returns login verification codes in HTTP resp ...)
-	TODO: check
+	NOT-FOR-US: X-SpringBoot
 CVE-2026-97060 (X-SpringBoot through 6.0 lacks object-level authorization in user mana ...)
-	TODO: check
+	NOT-FOR-US: X-SpringBoot
 CVE-2026-96883 (pgcollection is an open source extension to PostgreSQL. A type confusi ...)
 	NOT-FOR-US: Amazon
 CVE-2026-96874 (Improper neutralization of input during web page generation ('cross-si ...)
-	TODO: check
+	NOT-FOR-US: X-SpringBoot
 CVE-2026-96812 (Improper Exposure of Resource to Wrong Sphere in the host file helper  ...)
-	TODO: check
+	NOT-FOR-US: Google gVisor
 CVE-2026-96766 (The GeoDirectory \u2013 WP Business Directory Plugin and Classified Li ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-96752 (The Zero Spam for WordPress plugin for WordPress is vulnerable to Stor ...)
@@ -131,7 +131,7 @@ CVE-2026-95834 (Use After Free in the drag source path of the drag and drop prot
 CVE-2026-95832 (Improper Neutralization of Special Elements in Output Used by a Downst ...)
 	TODO: check
 CVE-2026-95699 (Prior to 9/18/2026, the iSteamX mobile application's AWS policy could  ...)
-	TODO: check
+	NOT-FOR-US: iSteamX mobile application
 CVE-2026-94573 (The Repeater Fields for Elementor Forms plugin for WordPress is vulner ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-94445 (A malicious txtar could escape the intended execution context and forc ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb8c765c91d27e0d45ae8dc40f36131feaa020c1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb8c765c91d27e0d45ae8dc40f36131feaa020c1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/f0fb080d/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list